THE DESIGN OPTIONS AND PROVISION FILE AND THE ROLE OF DEFENCE IN DEPTH WITHIN THE PRE-LICENSING OF THE MYRRHA
3. VOLUME 2: APPROACH TO NUCLEAR SAFETY 1. Introduction
3.2. Approach and steps of the design process
3.2.1. Implementation of the principles of defence in depth
The designer is requested to describe his/her approach in relation to the DID principles and justifying this approach versus references which can be considered as representative of the state of the art in terms of reflections on this subject. The document issued by WENRA [12] is certainly among the most representative. The refined structure of the DID levels proposed by WENRA/RHWG is presented in Figure 3.
19 Figure 3 provides clues for several concerns that are important for the design and the assessment of innovative installations. First it shows a one to one correspondence between the third level of the DID and all events / situations without core melting, including both the
“selected single initiating events” and the “selected multiple failure events”. Similarly the Figure shows the correspondence between the fourth level and the “postulated core melt accidents”. The proposal of WENRA/RHWG confirms that there is a direct relationship between the defence in depth and the “allowable risk domain” (column “Radiological consequences”). This relationship is essential for the designer who can so superpose the levels of defence in depth within the area of allowable risk, and simultaneously, to give explicit targets (success criteria, both in terms of performances and reliability) for these levels. These targets are essential to size the provisions that are associated with each level of the DID. This is perfectly coherent with the position expressed by the GIF/RSWG [13].
3.2.1.1. Structure and content of different levels of defence in depth
Following the logic shortly introduced within the previous section, the designer is requested to give insights – even if roughly described - about the way(s) for building the whole safety architecture of the installations in a manner that guarantees the compatibility with the principles of DID. The description should demonstrate that the selected approach will allow characterizing each level of DID: identifying the corresponding plant condition categories; defining the objectives of the DID level; identifying the means/provisions relied on to reach the objectives of the DID levels; defining de maximum expected radiological consequences (on the workers, the public and on the environment).
3.2.1.2. Approach to the design of the safety architecture to integrate defence in depth
As indicated by Figure 4, the design process for innovative systems should be iterative.
For each of the fundamental safety functions (left side of Figure 4 – possibly developed in several sub functions if needed) the designer should identify possible challenges, as well as the mechanisms that can, given the characteristics of the installation, materialize these challenges. The next step is to identify provisions that should be implemented within the DID level to address these mechanisms (layer of provisions – IAEA terminology [6]), i.e. to control and minimize their consequences and to avoid further deterioration while ensuring the achievement and the keeping of a controlled and safe plant state. The iterations continue for each level of defence in depth by integrating, at each step, both specific initiating events and the additional possibility of failure introduced by the implementation of new provisions.
3.2.2. Categorization of the “plant conditions” or “plant states” used for the design
The designer shall select the methodology for the event categorization. Figure 5 shows the consistency between the methods suggested by the IAEA Glossary2, by WENRA [12] and by the EUR [14] for the categorization of the “plant conditions” or “plant states” (i.e. the postulated initiating events) which are used for the design of the installation.
2 IAEA Glossary Ed. 2007
20
FIG. 3. WENRA / RHWG: Refined structure of the levels of did [12].
3.2.3. Stages of the design process
Finally the designer shall discuss its approach for the different stages of the design process which can be resumed as follows: definition, for each level of defence in depth, of quantitative objectives and goals of nuclear safety of the installation and radiation protection;
for each level of defence in depth, identification of phenomena (challenges) and failure mechanisms (initiating events) for the safety functions; consideration of the internal and external hazards; categorization of initiating events and hazards retained for the design. The designer is invited to comment each of these stages and to present the corresponding engaged or planned efforts.
3.2.4. Principles for selecting design options and sizing provisions for the different levels of DID
The basic idea for this DOPF section is to provide insights about the methodology implemented by the designer to translate the goals and objectives of the various levels of the defence in depth, as well as generic principles, requirements and guidelines, first into safety design options and later - i.e., once selected the due solution/provision - into design and operational safety specifications/ criteria applicable to the design. The regulator should be able to appreciate how far safety is “built in” rather than “added on” (cf. [13], [15]). The section provides the list of generic and technology neutral requirements selected among those
21 available within the available references (IAEA, INSAG, others), applicable to improve the prevention, the surveillance, the accident management and the severe accident management for future installations; it should also present how the designer develops such requirements in order to obtain design and operational safety specifications.
FIG. 4. Iterative process for the construction of the safety architecture [3].
FIG. 5. Possible categorization of the plant states.
22
3.2.5. Rules for plant operation
As for the previous section, the basic idea is to discuss how the content of the various levels of defence in depth is translated into design and operational safety specifications / criteria applicable to the selection of operating procedures for normal, abnormal as well as accidental conditions.
3.2.6. Crosscutting themes for the design
The designer is requested to present and comment his strategy on different safety related themes such as: Classification of provisions important to safety; Consideration of the human factor; Consideration of Common Cause Failures; Reliability and availability of SSCs;
Consideration of feedback experience; Consideration of maintenance conditions;
Consideration of inadequate accessibility for testing and maintenance; Consideration of dismantling conditions; Consideration of the state of the art and R & D programs.